Bugzilla – Bug 1220157
VUL-0: CVE-2024-25711: diffoscope: information disclosure vulnerability when diffing GPG artifacts
Last modified: 2024-03-24 19:35:03 UTC
Use a determistic name when extracting content from GPG artifacts instead of trusting the value of gpg's --use-embedded-filenames. This prevents a potential information disclosure vulnerability that could have been exploited by providing a specially-crafted GPG file with an embedded filename of, say, "../../.ssh/id_rsa". Many thanks to Daniel Kahn Gillmor <dkg@debian.org> for reporting this issue and providing feedback. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-25711 https://bugzilla.redhat.com/show_bug.cgi?id=2264735 https://salsa.debian.org/reproducible-builds/diffoscope/-/issues/361 Patch: https://salsa.debian.org/reproducible-builds/diffoscope/-/commit/458f7f04bc053a0066aa7d2fd3251747d4899476
Tracking as affected: - openSUSE:Backports:SLE-15-SP5/diffoscope 85 - openSUSE:Factory/diffoscope 251 CVE fixed in version 256 (https://diffoscope.org/news/diffoscope-256-released/)
This is an autogenerated message for OBS integration: This bug (1220157) was mentioned in https://build.opensuse.org/request/show/1161156 Factory / diffoscope